CVE-2026-53964High· 7.2▾ TwilightDocument Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnerability is limited to XLSX templates, were the xltpl library uses a npn-sandboxed Jinja environment for the processing of the template.
It has been patched in v9.1.0
Disable the upload/usage of XLSX templates.
Are there any links users can visit to find out more?
https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection/jinja2-ssti
document-merge-service < 9.1.0Upgrade to a patched release:
document-merge-service 9.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-37301High· 7.2document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
CVE-2026-37004Critical· 9.8LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-54653High· 8.8`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
CVE-2026-54654High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
CVE-2026-54621High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
CVE-2026-46439High· 7.8compliance-trestle is a tooling platform for managing compliance as code